NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67781 | CVE-2005-2072 | The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT. | 2 | 7.2 | High | 2017-01-03 | 2011-10-11 | View | |
2757 | CVE-2008-2863 | Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
3013 | CVE-2008-3129 | Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value paramter in the news page and (2) webpage parameter in the webpage_multi_edit form. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
3269 | CVE-2008-3388 | Multiple SQL injection vulnerabilities in Def-Blog 1.0.3 allow remote attackers to execute arbitrary SQL commands via the article parameter to (1) comaddok.php and (2) comlook.php. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
3525 | CVE-2008-3657 | The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen. | 2 | 7.5 | High | 2017-01-03 | 2011-07-13 | View |
Page 15701 of 17672, showing 5 records out of 88360 total, starting on record 78501, ending on 78505